{
  "day": "2026-09-24",
  "boundary": "UTC calendar day",
  "published_count": 553,
  "by_severity": {
    "CRITICAL": 28,
    "HIGH": 174,
    "MEDIUM": 120,
    "LOW": 30
  },
  "kev_count": 0,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 201,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-92905",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0235,
      "epss_percentile": 0.82955,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine EventLog Analyzer",
      "cwe": "CWE-248",
      "title": "Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92905"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-12227",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00769,
      "epss_percentile": 0.53634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "visualcomposer",
      "product": "Visual Composer Website Builder",
      "cwe": "CWE-98",
      "title": "Visual Composer Website Builder <= 45.16.0 - Unauthenticated Local File Inclusion via 'vcv-template' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12227"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-82077",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00738,
      "epss_percentile": 0.52527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PaperCut",
      "product": "PaperCut NG/MF",
      "cwe": "CWE-22",
      "title": "PaperCut NG/MF: Remote Code Execution via Scan2Fax",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82077"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-96891",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00653,
      "epss_percentile": 0.4906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DIR-825",
      "cwe": "CWE-119",
      "title": "D-Link DIR-825 rp-l2tp tunnel.c tunnel_set_params out-of-bounds write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96891"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-78313",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00463,
      "epss_percentile": 0.37379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Deltaww",
      "product": "DIAEnergie",
      "cwe": "CWE-284",
      "title": "Improper Access Control in DIAEnergie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78313"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-96898",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00424,
      "epss_percentile": 0.34004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yhx070424",
      "product": "ShopXO",
      "cwe": "CWE-22",
      "title": "yhx070424 ShopXO Ueditor Upload ueditor.php path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96898"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-97055",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00406,
      "epss_percentile": 0.32074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SigNoz",
      "product": "signoz",
      "cwe": "CWE-1188",
      "title": "SigNoz before 0.143.0 Authentication Bypass via Empty JWT Secret",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97055"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-18467",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00392,
      "epss_percentile": 0.30546,
      "kev": false,
      "kev_due_at": null,
      "vendor": "paytiumsupport",
      "product": "Paytium: Mollie payment forms & donations",
      "cwe": "CWE-269",
      "title": "Paytium: Mollie payment forms & donations <= 5.0.3 - Unauthenticated Privilege Escalation via 'pt_form_field[pt-user-role]' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18467"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-87739",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00378,
      "epss_percentile": 0.28964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PaperCut",
      "product": "PaperCut NG/MF",
      "cwe": "CWE-639",
      "title": "PaperCut MF/NG: User permissions are not evaluated on report generation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87739"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-77193",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00364,
      "epss_percentile": 0.27463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eesywp",
      "product": "eesy_ID2WP – Publish InDesign HTML5",
      "cwe": "CWE-22",
      "title": "eesy_ID2WP – Publish InDesign HTML5 <= 1.0.3 - Unauthenticated Path Traversal to Arbitrary File Read via 'id2wp_path' Query Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77193"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-97151",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00355,
      "epss_percentile": 0.26522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mwilliamson",
      "product": "mammoth.js",
      "cwe": "CWE-1321",
      "title": "mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a document. Converting a crafted .docx file allows an attacker to add arbitrary properties to Object.prototype. In 1.11.0 through 1.12.1, applications that convert further documents in the same process and return the converted HTML can also disclose the contents of local server files (to the party supplying the documents) by setting externalFileAccess to true.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97151"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-97056",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0035,
      "epss_percentile": 0.258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SigNoz",
      "product": "signoz",
      "cwe": "CWE-613",
      "title": "SigNoz before 0.143.0 Insufficient Session Expiration Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97056"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-78308",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00346,
      "epss_percentile": 0.25343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Deltaww",
      "product": "DIAEnergie",
      "cwe": "CWE-287",
      "title": "Authentication Bypass in DIAEnergie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78308"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-78312",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00345,
      "epss_percentile": 0.2517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Deltaww",
      "product": "DIAEnergie",
      "cwe": "CWE-22",
      "title": "Path Traversal in DIAEnergie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78312"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-96892",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00336,
      "epss_percentile": 0.24235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "BR-6428nC",
      "cwe": "CWE-601",
      "title": "Edimax BR-6428nC goform websRedirect redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96892"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-96884",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00335,
      "epss_percentile": 0.24062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "MantisZip",
      "cwe": "CWE-22",
      "title": "MantisZip Preview MainWindow.UI.cs Path.Combine path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96884"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-97152",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00313,
      "epss_percentile": 0.21511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nanomsg",
      "product": "Nanomsg",
      "cwe": "CWE-122",
      "title": "Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version header, through snprintf.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97152"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-14780",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.21327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PaperCut",
      "product": "PaperCut NG/MF",
      "cwe": "CWE-94",
      "title": "PaperCut NG/MF: Remote Code Execution via Scripting Subsystem",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14780"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-96772",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00292,
      "epss_percentile": 0.19356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Intelliants",
      "product": "Subrion CMS",
      "cwe": "CWE-200",
      "title": "Intelliants Subrion CMS actions.json assign-owner information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96772"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-96774",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.18774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SPON Communications",
      "product": "IP Network Audio Device XC-9603",
      "cwe": "CWE-200",
      "title": "SPON Communications IP Network Audio Device XC-9603 Configuration File Download sys_cfg.txt loadCfg information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96774"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-96880",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.18774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TaleLin",
      "product": "lin-cms-spring-boot",
      "cwe": "CWE-266",
      "title": "TaleLin lin-cms-spring-boot book Endpoint BookController.java getBook improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96880"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-96881",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.18774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TaleLin",
      "product": "lin-cms-spring-boot",
      "cwe": "CWE-266",
      "title": "TaleLin lin-cms-spring-boot book Endpoint BookController.java getBooks improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96881"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-96882",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.18773,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TaleLin",
      "product": "lin-cms-spring-boot",
      "cwe": "CWE-266",
      "title": "TaleLin lin-cms-spring-boot book Endpoint BookController.java searchBook improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96882"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-96764",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00271,
      "epss_percentile": 0.17154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kvcache-ai",
      "product": "mooncake",
      "cwe": "CWE-400",
      "title": "kvcache-ai mooncake Regular Expression GetReplicaListByRegex allocation of resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96764"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-97181",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.15867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ezGlobal",
      "product": "GPM LIGHT",
      "cwe": "CWE-497",
      "title": "ezGlobal｜GPM LIGHT - Sensitive Data Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97181"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-18335",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.15346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeum",
      "product": "Kirki – Freeform Page Builder, Website Builder & Customizer",
      "cwe": "CWE-918",
      "title": "Kirki – Freeform Page Builder, Website Builder & Customizer <= 6.2.0 - Unauthenticated Blind Server-Side Request Forgery via 'kirki_data' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18335"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-96803",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.15043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "java110",
      "product": "MicroCommunity",
      "cwe": "CWE-74",
      "title": "java110 MicroCommunity fallBack API Endpoint BusinessApi.java QueryServiceSMOImpl.fallBack sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96803"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-15731",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.14457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "magazine3",
      "product": "WP Multilang – Translation and Multilingual Plugin",
      "cwe": "CWE-79",
      "title": "WP Multilang – Translation and Multilingual Plugin <= 2.4.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15731"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-96773",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0025,
      "epss_percentile": 0.14442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Intelliants",
      "product": "Subrion CMS",
      "cwe": "CWE-601",
      "title": "Intelliants Subrion CMS Login Page login.php authorize redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96773"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-96763",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00247,
      "epss_percentile": 0.14207,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kvcache-ai",
      "product": "mooncake",
      "cwe": "CWE-266",
      "title": "kvcache-ai mooncake MountSegment Request Processing segment.cpp access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96763"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-78309",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.13289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Deltaww",
      "product": "DIAEnergie",
      "cwe": "CWE-89",
      "title": "SQL Injection in DIAEnergie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78309"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-78311",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.13289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Deltaww",
      "product": "DIAEnergie",
      "cwe": "CWE-89",
      "title": "SQL Injection in DIAEnergie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78311"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-97177",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.13059,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-862",
      "title": "Keycloak-services: keycloak-services: generic user update bypasses denied reset-password permission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97177"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-97149",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00226,
      "epss_percentile": 0.11805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Swift",
      "cwe": "CWE-184",
      "title": "In OpenStack Swift before 2.38.2, the tempurl middleware does not reject the X-Copy-From header on PUT requests. A TempURL signature only covers the method, expiry, and path, and thus the list of disallowed headers is the only defense against a signed PUT request changing what the request does. An attacker holding a PUT TempURL for a single object can add an X-Copy-From header naming any object in the same account; the copy middleware copies that object to the destination, and the attacker then reads the victim's data back with a GET TempURL for the destination object. Copies across account boundaries are rejected. Only deployments using the shipped default proxy pipeline (tempurl and copy middleware) with account-level TempURL keys are affected.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97149"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-78310",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.10333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Deltaww",
      "product": "DIAEnergie",
      "cwe": "CWE-639",
      "title": "Authorization Bypass Through User-Controlled Key in DIAEnergie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-78310"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-80513",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.09045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "wpForo Forum",
      "cwe": "CWE-502",
      "title": "wpForo Forum < 3.1.6 - Subscriber+ PHP Object Injection via Profile Fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80513"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-96777",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.08733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Forma",
      "product": "LMS",
      "cwe": "CWE-74",
      "title": "Forma LMS Multi-User-Selector AJAX Endpoint getData getDataTask sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96777"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-96810",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00191,
      "epss_percentile": 0.07726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "huanzi-qch",
      "product": "base-admin",
      "cwe": "CWE-79",
      "title": "huanzi-qch base-admin Add User CommonController.java save cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96810"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-57590",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.06726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache DolphinScheduler",
      "cwe": "CWE-863",
      "title": "Apache DolphinScheduler: Missing Authorization in Task Group APIs Allows Unauthorized Cross-Project Operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57590"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-11744",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00169,
      "epss_percentile": 0.05414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PaperCut",
      "product": "PaperCut Hive",
      "cwe": "CWE-79",
      "title": "PaperCut Hive Embedded App for Ricoh: Javascript injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11744"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-97176",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00167,
      "epss_percentile": 0.05293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-862",
      "title": "Keycloak-services: keycloak-services: essential acr requirement silently bypassed via cookie authenticator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97176"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-84151",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00164,
      "epss_percentile": 0.04902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "The Post Grid",
      "cwe": "CWE-79",
      "title": "The Post Grid < 7.9.5 - Contributor+ Stored HTML/iframe Injection via wp_kses_post Allow-List Widening",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84151"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-88843",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00157,
      "epss_percentile": 0.04103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MasterStudy LMS WordPress Plugin",
      "cwe": "CWE-22",
      "title": "MasterStudy LMS 3.5.29 - < 3.7.50 - Contributor+ LFI via Elementor Courses Categories Widget",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88843"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-89002",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.0363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPeMatico RSS Feed Fetcher",
      "cwe": "CWE-79",
      "title": "WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Stored XSS via Campaign Item Preview",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89002"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-89005",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.03631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPeMatico RSS Feed Fetcher",
      "cwe": "CWE-79",
      "title": "WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Stored XSS via Word to Category",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89005"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-89004",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00147,
      "epss_percentile": 0.0322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPeMatico RSS Feed Fetcher",
      "cwe": "CWE-639",
      "title": "WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Campaign Configuration and Log Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89004"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-82195",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00144,
      "epss_percentile": 0.0299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "10Web Booster",
      "cwe": "CWE-862",
      "title": "10Web Booster < 2.34.0 - Unauthenticated Connection Secret Disclosure and Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82195"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-82850",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.02667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Masteriyo LMS",
      "cwe": "CWE-200",
      "title": "Masteriyo LMS < 3.4.2 - Subscriber+ Quiz Answer Key Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82850"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-93662",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.02667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Events Manager",
      "cwe": "CWE-200",
      "title": "Events Manager 7.4.1 - 7.4.4 - Subscriber+ Unpublished Event and Location Disclosure via 'owner' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93662"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-74991",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.02476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPForms",
      "cwe": "CWE-284",
      "title": "WPForms Lite 1.8.8.2 - 2.0.1.1 - Unauthenticated Stripe Refund and Subscription Cancellation via External PaymentIntent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-74991"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-88846",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.02476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MasterStudy LMS WordPress Plugin",
      "cwe": "CWE-862",
      "title": "MasterStudy LMS 2.3.0 - < 3.7.50 - Unauthenticated Account Creation with Registration Disabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88846"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-85682",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00135,
      "epss_percentile": 0.02426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yourownprogrammer",
      "product": "YOP Poll",
      "cwe": "CWE-346",
      "title": "YOP Poll <= 7.0.10 - Unauthenticated Origin Validation Error to Administrator Account Takeover via '/auth/wp-login-redirect' REST Route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85682"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-97185",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00133,
      "epss_percentile": 0.02311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-787",
      "title": "Gimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97185"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-80338",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.02275,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "CMB2",
      "cwe": "CWE-862",
      "title": "CMB2 < 2.13.0 - Subscriber+ Arbitrary Option Corruption via oEmbed Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-80338"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-82849",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.02254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Masteriyo LMS",
      "cwe": "CWE-639",
      "title": "Masteriyo LMS < 3.4.2 - Subscriber+ Arbitrary User Course Progress Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82849"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-88845",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.02254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MasterStudy LMS WordPress Plugin",
      "cwe": "CWE-862",
      "title": "MasterStudy LMS 2.3.0 - < 3.7.50 - Subscriber+ Course and Lesson Creation via Demo Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88845"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-88847",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.02254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MasterStudy LMS WordPress Plugin",
      "cwe": "CWE-862",
      "title": "MasterStudy LMS < 3.7.50 - Subscriber+ Lesson Completion Record Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88847"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-93661",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00132,
      "epss_percentile": 0.02253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Events Manager",
      "cwe": "CWE-639",
      "title": "Events Manager < 7.4.5 - Contributor+ Arbitrary Ticket Overwrite via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93661"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-97155",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fabasoft",
      "product": "Folio Client",
      "cwe": "CWE-346",
      "title": "Fabasoft Folio Client before 2026, a locally installed component that communicates with the Fabasoft browser extension via web messaging, does not restrict which web origins may invoke its functions by default. The registry value VALIDDOMAINS, which limits permitted origins, was optional and empty by default, resulting in all domains being trusted. As a consequence, any website visited by a user with the Folio Client and browser extension installed could invoke client functions, e.g., related to downloading documents, opening documents, and synchronizing files. The first fixed builds are Fabasoft Folio Client 2026 (Build 26.0.0.10) and Fabasoft Folio Client 2026 April Release (Build 26.4.0.76). This client is, for example, shipped with Fabasoft eGov-Suite.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97155"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-81645",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00088,
      "epss_percentile": 0.00372,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read vulnerability in the graphics module. Successful exploitation of this vulnerability may affect availability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81645"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-61732",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BitterSecurity",
      "product": "Decepticon",
      "cwe": "CWE-74",
      "title": "Decepticon: Role-boundary forgery via ChatML special-token literals in web crawl output composed into LLM context",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61732"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-97359",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rejetto",
      "product": "hfs2",
      "cwe": "CWE-1336",
      "title": "HFS2 2.4.0 RCE via Multipart Upload Filename Template Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97359"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-97360",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rejetto",
      "product": "hfs2",
      "cwe": "CWE-862",
      "title": "HFS2 2.4.0 Unauthenticated Arbitrary File Read/Write via Template Engine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97360"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-19072",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "Velociraptor",
      "cwe": "CWE-164",
      "title": "Velociraptor Investigator reaches SuperUser via hunt EffectivePrincipal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19072"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-93425",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokploy",
      "product": "dokploy",
      "cwe": "CWE-78",
      "title": "Dokploy: Authenticated OS Command Injection in patch.readRepoDirectories (repoPath) leads to RCE as root",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93425"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-13249",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Honeywell",
      "product": "PD45 Industrial Printer",
      "cwe": "CWE-78",
      "title": "Unauthenticated RCE Arbitrary File Upload Honeywell PD45 Industrial Printer version F10.19.010040",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13249"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-93207",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "SUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93207"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-97413",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/rtrs-srv: Fix integer underflow in process_read and process_write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97413"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-81549",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-918",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81549"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-13016",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ServiceNow",
      "product": "ServiceNow AI Platform",
      "cwe": "CWE-89",
      "title": "Unauthenticated SQL Injection in ServiceNow AI Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13016"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-61604",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ixofoundation",
      "product": "ixo-blockchain",
      "cwe": "CWE-285",
      "title": "ixo Blockchain x/bonds DID-resolved payer drain + x/entity ICA authorization bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61604"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-61741",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "http4s",
      "product": "http4s-scala-xml",
      "cwe": "CWE-611",
      "title": "http4s-scala-xml has an XML External Entity (XXE) processing issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61741"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-61742",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bytebase",
      "product": "dbhub",
      "cwe": "CWE-306",
      "title": "DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61742"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-86860",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ServiceNow",
      "product": "ServiceNow AI Platform",
      "cwe": "CWE-862",
      "title": "Unauthenticated Sensitive Data Disclosure in ServiceNow AI Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86860"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-91187",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dashbit",
      "product": "nimble_zta",
      "cwe": "CWE-347",
      "title": "Improper Verification of Cryptographic Signature in dashbit nimble_zta Cloudflare strategy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91187"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-93291",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eufy",
      "product": "Omni C20",
      "cwe": "CWE-295",
      "title": "Improper certificate validation in Eufy Omni C20",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93291"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-81630",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Botslab",
      "product": "G980H",
      "cwe": "CWE-345",
      "title": "Botslab G980H Dashcams Insufficient Verification of Data Authenticity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81630"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-90481",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PortSwigger",
      "product": "Burp Suite DAST",
      "cwe": "CWE-288",
      "title": "In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occur via an alternate path or channel.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90481"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-97404",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Zaqar",
      "cwe": "CWE-348",
      "title": "In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request with an empty URL-Signature header, an unauthenticated remote attacker who knows a target project's UUID may bypass both Keystone authentication and pre-signed URL verification, resulting in the ability to read, enumerate, create, and delete that project's queues, messages, claims, and subscriptions. By additionally claiming an administrative role, the attacker may also perform administrative operations, such as managing pools and flavors in admin_mode deployments. Only deployments using the WSGI transport with an authentication strategy configured are affected; the websocket transport is not affected.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97404"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-79766",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Termix-SSH",
      "product": "Termix",
      "cwe": "CWE-78",
      "title": "Termix: OS command injection in ACME/Let's Encrypt certificate-request handler via admin-controlled domain/email",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79766"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-93228",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "svcrdma: Reject Write/Reply chunks with segcount 0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93228"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-93289",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eufy",
      "product": "Omni C20",
      "cwe": "CWE-78",
      "title": "OS command injection in Eufy Omni C20, Omni X10 Pro",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93289"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-94606",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "goauthentik",
      "product": "authentik",
      "cwe": "CWE-287",
      "title": "authentik: MFA Bypass via State Confusion / Parameter Injection in AuthenticatorEmailStage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94606"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-13248",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Honeywell",
      "product": "PD45 Industrial Printer",
      "cwe": "CWE-73",
      "title": "Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13248"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-81539",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-78",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81539"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-81545",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-78",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81545"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-81547",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-22",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81547"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-81548",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-78",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81548"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-81552",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-78",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81552"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-82093",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-502",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82093"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-93280",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "greybus: audio: bound the topology section sizes against the fetched size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93280"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-93284",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/pagemap: dma-unmap pages before handling migration errors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93284"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-93790",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: iwlwifi: mvm: fix out-of-bounds tid_data access in BA notif",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93790"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-93793",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: iwlwifi: mvm: validate TX_CMD response layout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93793"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-93799",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: iwlwifi: mvm: validate sta_id in BA window status notif",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93799"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-93806",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: cfg80211: validate assoc response length before status and IE access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93806"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-94609",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "goauthentik",
      "product": "authentik",
      "cwe": "CWE-269",
      "title": "authentik: Privilege Escalation to Superuser via Group Hierarchy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94609"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-97059",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OFFIS",
      "product": "DCMTK",
      "cwe": "CWE-125",
      "title": "DCMTK through 3.7.0 Heap Over-read via NumberOfFrames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97059"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-97409",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvme-fc: Do not cancel requests in io target before it is initialized",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97409"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-97442",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: ath11k: fix invalid data access in ath11k_dp_rx_h_undecap_nwifi",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97442"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-97509",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "thunderbolt: Keep XDomain reference during the lifetime of a service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97509"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-56744",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bsv-blockchain",
      "product": "@bsv/wallet-toolbox",
      "cwe": "CWE-1288",
      "title": "`@bsv/wallet-toolbox` / `-client` / `-mobile` don't verify storage-supplied recipient output scripts against caller-requested outputs in createAction (can redirect payments when using remote storage)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56744"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-61825",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code16",
      "product": "sharp",
      "cwe": "CWE-79",
      "title": "code16/sharp has a stored XSS via data-html-content Sanitizer Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61825"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-63498",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-79",
      "title": "Snipe-IT: Stored XSS via Inline XML Rendering in the Uploaded Files API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63498"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-82566",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Botslab",
      "product": "G980H",
      "cwe": "CWE-613",
      "title": "Botslab G980H Dashcams Insufficient session expiration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82566"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-84399",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Botslab",
      "product": "G980H",
      "cwe": "CWE-863",
      "title": "Botslab G980H Dashcams Incorrect Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84399"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-85057",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zitadel",
      "product": "zitadel",
      "cwe": "CWE-284",
      "title": "ZITADEL: Actions V1 sandbox escape: host file read via require()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85057"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-86858",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ServiceNow",
      "product": "ServiceNow AI Platform",
      "cwe": "CWE-284",
      "title": "Unauthenticated Privilege Escalation via GraphQL in ServiceNow AI Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86858"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-86859",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ServiceNow",
      "product": "ServiceNow AI Platform",
      "cwe": "CWE-284",
      "title": "Unauthenticated Arbitrary Record Disclosure in ServiceNow AI Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86859"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-87721",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gerrit",
      "product": "Gerrit",
      "cwe": "CWE-400",
      "title": "Denial of Service via Exponential Backtracking in ANTLR Search Query Parser in Gerrit Code Review",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87721"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-87722",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gerrit",
      "product": "Gerrit",
      "cwe": "CWE-400",
      "title": "Regular Expression Denial of Service (ReDoS) in Search Query Predicates and REST Filter Endpoints in Gerrit Code Review",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87722"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-91122",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-79",
      "title": "Discourse: Chat MessageBus delivers read-restricted messages to unauthorized users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91122"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-96883",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "pgcollection",
      "cwe": "CWE-843",
      "title": "Type confusion in AWS pgcollection allows remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96883"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-97057",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NodeRedis",
      "product": "redis-parser",
      "cwe": "CWE-1284",
      "title": "redis-parser through 3.0.0 Denial of Service via Invalid Array Length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97057"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-97362",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rejetto",
      "product": "hfs2",
      "cwe": "CWE-835",
      "title": "HFS2 2.4.0 Unauthenticated Denial of Service via Hung Serving Thread",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97362"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-63493",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-288",
      "title": "Snipe-IT: 2FA bypass via the API token flow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63493"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-77581",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "alam00000",
      "product": "bentopdf",
      "cwe": "CWE-918",
      "title": "BentoPDF: SSRF in cors-proxy-worker.js via DNS-based hostname allowlist bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77581"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-77874",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Enterprise Build of Quarkus",
      "cwe": "CWE-89",
      "title": "IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77874"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-77967",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Botslab",
      "product": "G980H",
      "cwe": "CWE-294",
      "title": "Botslab G980H Dashcams Authentication Bypass by Capture-replay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77967"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-81455",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "ThinOS 10",
      "cwe": "CWE-306",
      "title": "Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81455"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-95985",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Amazon",
      "product": "Kiro IDE",
      "cwe": "CWE-349",
      "title": "Kiro IDE Allows Agentic Writes to Global Configurations While Working in Untrusted Workspaces",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95985"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-96515",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netlink ICT Pvt Ltd",
      "product": "Netlink ICT HG323RW Router",
      "cwe": "CWE-434",
      "title": "Command Injection Vulnerability in Netlink ICT HG323RW Router",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96515"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-56738",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-89",
      "title": "phpMyFAQ has SQL Injection in `StopWords::add()` — Unescaped Stop Word Insertion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56738"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-56739",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "logto-io",
      "product": "logto",
      "cwe": "CWE-918",
      "title": "Logto: SSRF via Webhooks and Custom OAuth2 Connector UserInfo Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56739"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-82371",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brocade",
      "product": "SANnav",
      "cwe": "CWE-532",
      "title": "Plaintext exposure of sensitive authentication data in SANnav discovery service log files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82371"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-82372",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brocade",
      "product": "SANnav",
      "cwe": "CWE-532",
      "title": "Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav before 3.0.1.a",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82372"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-85082",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Maple Media",
      "product": "Root Browser Classic",
      "cwe": "CWE-78",
      "title": "Maple Media Root Browser Classic 3.3.0 - OS command injection through crafted SQLite filenames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85082"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-93354",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gimanh",
      "product": "taskview-community",
      "cwe": "CWE-1188",
      "title": "Taskview Community Missing Authentication via OAuth Dynamic Client Registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93354"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-14443",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brocade",
      "product": "SANnav",
      "cwe": "CWE-532",
      "title": "Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav before 3.0.1a",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14443"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-86857",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ServiceNow",
      "product": "ServiceNow AI Platform",
      "cwe": null,
      "title": "Authorization Bypass in ServiceNow AI Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-86857"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-93827",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "virtio-fs: avoid double-free on failed queue setup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93827"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-95699",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MrSteam",
      "product": "iSteamX application",
      "cwe": "CWE-653",
      "title": "MrSteam iSteamX Improper Isolation or Compartmentalization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95699"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-97450",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ACPICA: validate handler object type in two places",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97450"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-97451",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ACPICA: Fix integer overflow in acpi_ex_opcode_3A_1T_1R() (mid_op)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97451"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-97452",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ACPICA: Prevent adding invalid references",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97452"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-97455",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ACPICA: Fix use-after-free in acpi_ds_terminate_control_method()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97455"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-13465",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Altera",
      "product": "Trusted Firmware",
      "cwe": "CWE-121",
      "title": "EL3 Stack Buffer Overflow in FCS HKDF Request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13465"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-13466",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Altera",
      "product": "Trusted Firmware",
      "cwe": "CWE-131",
      "title": "Unit Confusion in VAB Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13466"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-13467",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Altera",
      "product": "Trusted Firmware",
      "cwe": "CWE-787",
      "title": "Systemic Missing Address Validation in SiP SMC Handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13467"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-58004",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Altera",
      "product": "Trusted Firmware",
      "cwe": "CWE-125",
      "title": "Crafted oversized firmware image causes EL3 stack overflow during VAB authentication on Trusted Firmware.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58004"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-58005",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Altera",
      "product": "Trusted Firmware",
      "cwe": "CWE-119",
      "title": "Unvalidated SiP v2 mailbox pointers allow non-secure EL1 access to arbitrary physical addresses through EL3.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58005"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-58006",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Altera",
      "product": "Trusted Firmware",
      "cwe": "CWE-822",
      "title": "Altera SoCFPGA BL31 Mailbox Output Pointer Validation Enables EL3 Secure-Memory Corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58006"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-58007",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Altera",
      "product": "Trusted Firmware",
      "cwe": "CWE-822",
      "title": "Unchecked SDM mailbox response address enables EL3 secure-memory corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58007"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-58008",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Altera",
      "product": "Trusted Firmware",
      "cwe": "CWE-121",
      "title": "Unchecked HKDF key-size input in EL3 causes a stack buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58008"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-82157",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "ThinOS 10",
      "cwe": "CWE-295",
      "title": "Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Protection mechanism bypass and Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82157"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-96746",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "C Driver",
      "cwe": "CWE-787",
      "title": "Heap buffer overflow via mid-scan command list growth in client topology monitoring",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96746"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-96748",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "Python Driver",
      "cwe": "CWE-177",
      "title": "Connection redirection via percent-encoded delimiter injection in connection string hosts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96748"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-56736",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-79",
      "title": "phpMyFAQ has Stored XSS in Admin FAQ Editor via HTML Entity Bypass in Frontend FAQ Submission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56736"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-85056",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zitadel",
      "product": "zitadel",
      "cwe": "CWE-287",
      "title": "ZITADEL: MFA bypass via session reuse in Login V2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85056"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-91160",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rmyndharis",
      "product": "OpenWA",
      "cwe": "CWE-862",
      "title": "OpenWA: A read-only API key can receive a session pairing QR over the WebSocket event stream",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91160"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-97433",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvme: validate FDP configuration descriptor sizes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97433"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-56737",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-287",
      "title": "phpMyFAQ's two-factor authentication login bypasses the password factor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56737"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-62368",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-79",
      "title": "Snipe-IT: Stored XSS via Custom Field name in asset-list column headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62368"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-77294",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mauriceboe",
      "product": "TREK",
      "cwe": "CWE-918",
      "title": "TREK: Server-Side Request Forgery via User-Configurable LLM Base URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77294"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-81473",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Rugged Control Center (RCC)",
      "cwe": "CWE-287",
      "title": "Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81473"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-90959",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2",
      "cwe": "CWE-22",
      "title": "Pulpcore: pulpcore: file:// scheme allowlist bypass in content upload file_url field enables arbitrary file read and pulp container registry signing key theft",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-90959"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-93221",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: convert nfsd_net boolean flags to unsigned long flags word",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93221"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-93224",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "svcrdma: Fix unmatched rn_unregister on failed accept",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93224"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-93282",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: fix maximum allowed access checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93282"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-93786",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: preserve VFS inherited POSIX ACL mask",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93786"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-93787",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: bound dirent name against end of SMB response in cifs_filldir",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93787"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-94611",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "goauthentik",
      "product": "authentik",
      "cwe": "CWE-200",
      "title": "authentik: Stored credentials are readable with view permission alone",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94611"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-89325",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "Insight Agent",
      "cwe": "CWE-427",
      "title": "Rapid7 Insight Agent: Uncontrolled search path element in InsightVM assessment content leads to local privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-89325"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-93237",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "LoongArch: Add DIRECT_MAP_PHYSMEM_END definition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93237"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-93250",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vxlan: mdb: Fix use-after-free in vxlan_mdb_flush()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93250"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-93262",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "md/raid5-ppl: fix use-after-free in ppl_do_flush()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93262"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-93277",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/bnxt_re: Validate udata before executing commands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93277"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-93287",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "i2c: smbus: reject oversized block transfers in the common path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93287"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-93288",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet state",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93288"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-93782",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vhost-scsi: flush backend after device ioctls",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93782"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-93798",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: fix reloc root cleanup in merge_reloc_roots()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93798"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-93813",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: tree-checker: validate INODE_REF's namelen",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93813"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-93817",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "perf: Fix addr_filter_ranges lifetime",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93817"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-95519",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-78",
      "title": "Rpm: code execution via macro expansion of manifest entries in `rpmgi` (`-q -p` / verify manifest flows)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95519"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-95521",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-78",
      "title": "Rpm: rpm: shell command injection via macro expansion of source/spec file basenames when installing a source rpm",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-95521"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-97415",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97415"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-97421",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/umem: Be careful about boundary conditions in ib_umem_find_best_pgsz()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97421"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-97429",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdkfd: fix UAF race in destroy_queue_cpsch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97429"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-97478",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "virt: acrn: Fix irqfd use-after-free during eventfd shutdown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97478"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-97497",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdkfd: Check bounds for allocate_sdma_queue restore_sdma_id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97497"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-97513",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: chips-media: wave5: Release m2m_ctx after Instance Removed from List",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97513"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-79764",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Termix-SSH",
      "product": "Termix",
      "cwe": "CWE-918",
      "title": "Termix: Authenticated SSRF via `/homepage/proxy` — No Destination Allowlist",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79764"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-85496",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Botslab",
      "product": "G980H",
      "cwe": "CWE-340",
      "title": "Botslab G980H Dashcams Generation of Predictable Numbers or Identifiers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85496"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-88390",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-787",
      "title": "An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruino 2v29 (commit bffc6d0) allows crafted JavaScript input containing an overlong token to trigger a one-byte write beyond the JsLex.token buffer in RELEASE/NO_ASSERT builds. The out-of-bounds write corrupts the adjacent tokenValue pointer, resulting in memory corruption and potentially causing application crashes or denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88390"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-93265",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "PCI/pwrctrl: tc9563: Fix parsing the integrated Ethernet MAC Endpoint node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93265"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-97428",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: harden FRU PIA parsing with bounded helpers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97428"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-97444",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ACPICA: add boundary checks in two places",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97444"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-97445",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ACPICA: Enhance buffer validation in acpi_ut_walk_aml_resources()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97445"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-97448",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ACPICA: Add validation for node in acpi_ns_build_normalized_path()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97448"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-97454",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ACPICA: add boundary checks in acpi_ps_get_next_field()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97454"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-63203",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "logto-io",
      "product": "logto",
      "cwe": "CWE-862",
      "title": "Logto: Account API can disclose stored third-party provider tokens without the identities scope",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63203"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-87720",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gerrit",
      "product": "Gerrit",
      "cwe": "CWE-613",
      "title": "Incorrect Authorization via Stale ProjectCache Eviction and Repeated .git Suffixes in Gerrit Code Review",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87720"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-7169",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Evope Collector",
      "product": "Evope Collector",
      "cwe": null,
      "title": "Uncontrolled Search Path Element in Evope Collector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7169"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-51995",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-200",
      "title": "An issue in geelen mcp-remote 0.1.32 through 0.1.38 allows a remote attacker to obtain sensitive information via the src/lib/authorization-server-metadata.ts, src/lib/utils.ts components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51995"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-57440",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StarCitizenWiki",
      "product": "mediawiki-extensions-EmbedVideo",
      "cwe": "CWE-79",
      "title": "Mediawiki EmbedVideo Extension has stored XSS via malformed src url with $wgEmbedVideoRequireConsent disabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57440"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-61782",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "web-infra-dev",
      "product": "rsdoctor",
      "cwe": "CWE-200",
      "title": "@rsdoctor/rspack-plugin has Unauthenticated HTTP API that Exposes Project Source Code and Build Metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61782"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-61816",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zbateson",
      "product": "mail-mime-parser",
      "cwe": "CWE-400",
      "title": "zbateson/mail-mime-parser has uncontrolled resource consumption (CPU/memory DoS) parsing untrusted MIME",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61816"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-63645",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openobserve",
      "product": "openobserve",
      "cwe": "CWE-200",
      "title": "OpenObserve: Unauthenticated /config/runtime endpoint exposes PostgreSQL database credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63645"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-71540",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wazuh",
      "product": "wazuh",
      "cwe": "CWE-770",
      "title": "Wazuh Manager cluster header parsing allows pre-authentication memory exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-71540"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-75907",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Norwegian Cruise Line",
      "product": "door access control",
      "cwe": "CWE-287",
      "title": "CVE-2026-75907",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75907"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-88357",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-1335",
      "title": "nDPI 5.1.0 contains a memory access issue in the DNS dissector and serializer deserialization code. Specially crafted network input can cause byte-buffer addresses at odd offsets to be cast to uint16_t or wider integer pointers and directly dereferenced without alignment checks. This results in undefined behavior and can cause process termination in UBSan-instrumented builds or on strict-alignment architectures, leading to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88357"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-88368",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-681",
      "title": "NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in the rasterizer's nsvg__addActive() function. A specially crafted SVG document containing sufficiently large geometry coordinates can cause fixed-point-scaled edge coordinates to exceed the range representable by int. The rasterizer subsequently converts these values to int without range validation, resulting in undefined behavior and possible process termination, leading to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88368"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-88372",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-190",
      "title": "libsndfile 1.2.2 contains an integer overflow vulnerability in mat4_read_header() when parsing crafted MAT4 (MATLAB v4) files.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88372"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-88376",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-191",
      "title": "Bento4 1.6.0.0 contains an integer underflow vulnerability in AP4_AvccAtom::Create() and AP4_HvccAtom::Create(). A specially crafted MP4 file containing an avcC or hvcC atom with a declared size smaller than the atom header size can cause the payload-size calculation to wrap to a large unsigned value. The resulting invalid buffer allocation and copy operations can cause application termination, leading to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88376"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-88382",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-770",
      "title": "hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory allocation vulnerability in its RESP aggregate parser.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88382"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-93826",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "HID: hidpp: fix potential UAF in hidpp_connect_event()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93826"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-93830",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: stmmac: xgmac2: disable RBUE in default RX interrupt mask",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93830"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-94613",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "goauthentik",
      "product": "authentik",
      "cwe": "CWE-770",
      "title": "authentik: Denial of Service via Document Type Declarations in SAML Messages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94613"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-96749",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "Python Driver",
      "cwe": "CWE-190",
      "title": "Heap out-of-bounds write via signed size overflow in BSON document encoding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96749"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-97417",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97417"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-97508",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "thunderbolt: Set tb->root_switch to NULL when domain is stopped",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97508"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-57178",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "python-social-auth",
      "product": "social-core",
      "cwe": "CWE-287",
      "title": "social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57178"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-61788",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bytebase",
      "product": "dbhub",
      "cwe": "CWE-184",
      "title": "@bytebase/dbhub's read-only mode does not prevent database writes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61788"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-88907",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TÜBİTAK ULAKBİM",
      "product": "UlakPDF",
      "cwe": "CWE-863",
      "title": "SAML ePPN Attribute Validation Bypass in TÜBİTAK ULAKBİM's UlakPDF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88907"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-93225",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "phy: fsl-imx8mq-usb: fix typec switch leak on probe error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93225"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-93260",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "powerpc/xive: propagate IPI init errors to prevent use-after-free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93260"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-93543",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "x.org",
      "product": "libXi",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read in libXi's XI2 class parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93543"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-94612",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "goauthentik",
      "product": "authentik",
      "cwe": "CWE-287",
      "title": "authentik: Authentication bypass via assertion confusion in SAML sources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94612"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-97474",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: iwlwifi: mld: purge async notifications upon nic error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97474"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-12559",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenText",
      "product": "Vendor Invoice Management for SAP Solutions",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting (XSS) in OpenText Vendor Invoice Management for SAP Solutions Capture Validation Application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12559"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-61823",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code16",
      "product": "sharp",
      "cwe": "CWE-79",
      "title": "code16 Sharp vulnerable to stored XSS via iframe srcdoc Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61823"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-96750",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "Compass",
      "cwe": "CWE-94",
      "title": "Shell script injection via server-supplied database name in Open MongoDB shell",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96750"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-61815",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zbateson",
      "product": "mail-mime-parser",
      "cwe": "CWE-93",
      "title": "zbateson/mail-mime-parser has CRLF header injection via attachment filename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61815"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-91123",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-22",
      "title": "Discourse: Reject literal backslash path separators in iframe src traversal guard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91123"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-4638",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Paessler GmbH",
      "product": "PRTG Network Monitor",
      "cwe": "CWE-209",
      "title": "Plaintext Password Disclosure via VBScript Sensor Error Message in Paessler PRTG Network Monitor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4638"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-48070",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "docmost",
      "product": "docmost",
      "cwe": "CWE-22",
      "title": "Docmost: Avatar URL path traversal in avatar cleanup leads to arbitrary local file deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48070"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-77293",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mauriceboe",
      "product": "TREK",
      "cwe": "CWE-639",
      "title": "TREK: Cross-user note-file deletion (IDOR / Broken Access Control)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77293"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-82094",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataStage on Cloud Pak for Data",
      "cwe": "CWE-22",
      "title": "DataStage on Cloud Pak for Data has several vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82094"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-82164",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Trusted Device Client,",
      "cwe": "CWE-732",
      "title": "Dell Trusted Device Client, versions prior to 8.1.359.0, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82164"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-82585",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Botslab",
      "product": "G980H",
      "cwe": "CWE-319",
      "title": "Botslab G980H Dashcams Cleartext Transmission of Sensitive Information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82585"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-82708",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Botslab",
      "product": "G980H",
      "cwe": "CWE-22",
      "title": "Botslab G980H Dashcams Improper Limitation of a Pathname to a Restricted Directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82708"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-93229",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: add missing read barrier to rpc_status_get dumpit seqcount retry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93229"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-93816",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "f2fs: validate inline dentry name lengths before conversion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93816"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-96744",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "Laravel MongoDB (PHP)",
      "cwe": "CWE-943",
      "title": "Unauthorized cache lock takeover via expression injection in lock owner values in MongoDB integration for Laravel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96744"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-97437",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ntfs3: fix out-of-bounds read in ntfs_dir_emit() and hdr_find_e()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97437"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-97438",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fs/ntfs3: validate index entry key bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97438"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-97496",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdkfd: Fix OOB memory exposure in get_wave_state()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97496"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-97520",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "gfs2: move quota_init qc iterator increment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97520"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-79959",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Botslab",
      "product": "G980H",
      "cwe": "CWE-798",
      "title": "Botslab G980H Dashcams Use of Hard-coded Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79959"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-88956",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Botslab",
      "product": "G980H",
      "cwe": "CWE-306",
      "title": "Botslab G980H Dashcams Missing Authentication for Critical Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88956"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-93796",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: iwlwifi: pcie: null RX pointers after free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93796"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-93801",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb/client: zero-initialize stack-allocated cifs_open_info_data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93801"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-93810",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cachefiles: Fix double fput",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93810"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-14441",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brocade",
      "product": "SANnav",
      "cwe": "CWE-1025",
      "title": "Logic flaw in SANnav Java cache key handling object comparison handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14441"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-14442",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brocade",
      "product": "SANnav",
      "cwe": "CWE-532",
      "title": "Information exposure vulnerability in the job scheduling component of SANnav before 3.0.1a",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14442"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-84403",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Botslab",
      "product": "G980H",
      "cwe": "CWE-306",
      "title": "Botslab G980H Dashcams Missing Authentication for Critical Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84403"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-87118",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Botslab",
      "product": "G980H",
      "cwe": "CWE-787",
      "title": "Botslab G980H Dashcams Out-of-bounds Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-87118"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-97058",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "alexei",
      "product": "sprintf-js",
      "cwe": "CWE-1284",
      "title": "sprintf-js through 1.1.3 Denial of Service via Unbounded Precision",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97058"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-26054",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sumatrapdfreader",
      "product": "sumatrapdf",
      "cwe": "CWE-125",
      "title": "SumatraPDF: Heap out-of-bounds read in MOBI header parser.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26054"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-57176",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "python-social-auth",
      "product": "social-core",
      "cwe": "CWE-289",
      "title": "social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in Vend Backend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57176"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-84283",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FluteCode",
      "product": "Secure Folder",
      "cwe": "CWE-922",
      "title": "FluteCode Secure Folder 1.2 -Plaintext vault files in shared storage bypass the PIN gate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84283"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-88916",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TÜBİTAK ULAKBİM",
      "product": "UlakPDF",
      "cwe": "CWE-863",
      "title": "Admin Access Bypass via Header Fallback in TÜBİTAK ULAKBİM's UlakPDF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88916"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-92680",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Araxis",
      "product": "Merge",
      "cwe": "CWE-522",
      "title": "Araxis Merge insufficiently protected credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-92680"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-93290",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eufy",
      "product": "Omni C20",
      "cwe": "CWE-798",
      "title": "Use of Hard-coded Credentials in Eufy Omni C20",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93290"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-94416",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2",
      "cwe": "CWE-290",
      "title": "Aap-gateway: aap-gateway: authorization bypass via workload identity token forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94416"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-79761",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Termix-SSH",
      "product": "Termix",
      "cwe": "CWE-78",
      "title": "Termix: Command injection in SSH key deployment verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79761"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-4806",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "alexvtn",
      "product": "Custom Thank You Page for WooCommerce",
      "cwe": "CWE-862",
      "title": "Custom Thank You Page for WooCommerce <= 1.1.2 - Missing Authorization to Unauthenticated Settings Export and Settings Reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4806"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-54461",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HabitRPG",
      "product": "habitica",
      "cwe": "CWE-1333",
      "title": "Habitica: Regex Injection / ReDoS in Member Search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54461"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-61811",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wazuh",
      "product": "wazuh",
      "cwe": "CWE-674",
      "title": "Wazuh: Unbounded Recursion in os_xml `_getattributes()` Causes analysisd Worker Thread Stack Exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61811"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-65422",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Genetec Inc.",
      "product": "Genetec Security Center",
      "cwe": "CWE-862",
      "title": "A flaw in the authorization mechanism for Media Gateway API in Genetec Security Center may allow a user with no playback privileges to generate video thumbnails.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65422"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-65827",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "docmost",
      "product": "docmost",
      "cwe": "CWE-400",
      "title": "Docmost: Unbounded ZIP decompression (zip-bomb) in page import allows denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65827"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-76907",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "suitenumerique",
      "product": "docs",
      "cwe": "CWE-200",
      "title": "LaSuite Doc: Public Documents Enumeration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-76907"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-77798",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "Velociraptor",
      "cwe": "CWE-833",
      "title": "Velociraptor Authenticated Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77798"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-91133",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-943",
      "title": "Discourse: Escape LIKE metacharacters in upload paths to prevent disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91133"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-93541",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "X.org",
      "product": "libXi",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read in libXi's XQueryDeviceState()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93541"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-93542",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "x.org",
      "product": "libXi",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93542"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-93544",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "x.org",
      "product": "libXi",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93544"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-93545",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "x.org",
      "product": "libXi",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read in libXi's XListInputDevices()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93545"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-94281",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "x.org",
      "product": "libXi",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read in libXi's XListInputDevices() class parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-94281"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-57175",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "python-social-auth",
      "product": "social-core",
      "cwe": "CWE-287",
      "title": "social-auth-core has an Improper Authentication issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57175"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-79760",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Termix-SSH",
      "product": "Termix",
      "cwe": "CWE-918",
      "title": "Termix: Authenticated blind SSRF through notification channel test endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79760"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-91119",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-79",
      "title": "Discourse: Encode action_code_who in mention URLs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91119"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-91161",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rmyndharis",
      "product": "OpenWA",
      "cwe": "CWE-863",
      "title": "OpenWA: VIEWER API keys can read WhatsApp group invite codes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91161"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-85738",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "liketrek",
      "product": "TREK",
      "cwe": "CWE-918",
      "title": "TREK: SSRF Guard Bypass via IPv6 Transition Addresses (NAT64/6to4)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85738"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-96745",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "PHP Driver",
      "cwe": "CWE-502",
      "title": "PHP object injection via unsuppressible __pclass class inference in command monitoring events",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96745"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-6544",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Concert",
      "cwe": "CWE-552",
      "title": "Multiple Vulnerabilities in IBM Concert Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6544"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-61784",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cstigler",
      "product": "node-xhtml-purifier",
      "cwe": "CWE-79",
      "title": "xhtml-purifier has HTML attribute-injection (sanitizer bypass) that leads to XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61784"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-93405",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foundry376",
      "product": "Mailspring",
      "cwe": "CWE-79",
      "title": "Mailspring: Stored XSS in attachment quick preview (unsanitized Markdown/DOCX/XLSX conversion)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93405"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-67233",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-862",
      "title": "RabbitMQ: Monitoring-tag user can DELETE shovels",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67233"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-75558",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Botslab",
      "product": "G980H",
      "cwe": "CWE-321",
      "title": "Botslab G980H Dashcams Use of Hard-coded Cryptographic Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-75558"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-88761",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Botslab",
      "product": "G980H",
      "cwe": "CWE-1391",
      "title": "Botslab G980H Dashcams Use of Weak Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88761"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-93353",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "9001",
      "product": "copyparty",
      "cwe": "CWE-59",
      "title": "copyparty SFTP Volume Restriction Bypass via mkdir/rmdir/chattr Handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93353"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-77703",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HAVELSAN Inc.",
      "product": "Liman Render Engine",
      "cwe": "CWE-322",
      "title": "SSH Host Key Verification Bypass in HAVELSAN's Liman Render Engine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77703"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-77707",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HAVELSAN Inc.",
      "product": "Liman Render Engine",
      "cwe": "CWE-295",
      "title": "TLS Certificate Validation Disabled for Keycloak Connections in HAVELSAN's Liman Render Engine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77707"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-79762",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Termix-SSH",
      "product": "Termix",
      "cwe": "CWE-321",
      "title": "Termix: Hardcoded default key encrypts all OIDC/WebAuthn users' stored SSH credentials — full offline decryption from a database copy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79762"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-88384",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-476",
      "title": "OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribute parsing path. A specially crafted EXR file containing an unknown-type attribute with dataSize set to zero causes the parser to create an opaque attribute with a NULL packed_data pointer. The OpaqueAttribute constructor passes the NULL pointer to memcpy() without validating the zero-size condition, resulting in undefined behavior and process termination, leading to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88384"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-96873",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "Mediawiki - CirrusSearch Extension",
      "cwe": "CWE-79",
      "title": "Reflected XSS in CirrusSearch debug explain output",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96873"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-97182",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "halo-dev",
      "product": "Halo",
      "cwe": "CWE-20",
      "title": "halo-dev Halo SpEL ReplyNotificationSubscriptionHelper.java neutralization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97182"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-97231",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "volotat",
      "product": "Anagnorisis",
      "cwe": "CWE-287",
      "title": "volotat Anagnorisis Socket.IO Connect app.py missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97231"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-97324",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YunaiV",
      "product": "ruoyi-vue-pro",
      "cwe": "CWE-266",
      "title": "YunaiV/zhijiantianya ruoyi-vue-pro Demo-order Payment Callback PayDemoOrderController.java updateDemoOrderPaid improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97324"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-97326",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "songxinjianqwe",
      "product": "Chat",
      "cwe": "CWE-918",
      "title": "songxinjianqwe Chat chat-server ChatServer.java server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97326"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-47132",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-20",
      "title": "phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47132"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-79758",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Termix-SSH",
      "product": "Termix",
      "cwe": "CWE-284",
      "title": "Termix: Authenticated users can read other users' host status and clear global SSH connections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79758"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-91120",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-79",
      "title": "Discourse: Stored HTML injection in video notification emails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91120"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-91134",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-20",
      "title": "Discourse: Block post iframes whose encoded userinfo bypasses the allowed_iframes allowlist",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91134"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-19532",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HAVELSAN Inc.",
      "product": "Liman MYS",
      "cwe": "CWE-22",
      "title": "Path Traversal in HAVELSAN's Liman MYS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19532"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-48072",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "docmost",
      "product": "docmost",
      "cwe": "CWE-22",
      "title": "Docmost: Public image fileName path traversal leads to unauthorized local file read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48072"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-77320",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mauriceboe",
      "product": "TREK",
      "cwe": "CWE-200",
      "title": "TREK: Public trip share link ignores the `share_map` permission server-side (client-enforced authorization → itinerary/location disclosure)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77320"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-79763",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Termix-SSH",
      "product": "Termix",
      "cwe": "CWE-308",
      "title": "Termix: MFA-critical operations accept the account password as a sole factor (regression of CVE-2026-45749)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79763"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-96747",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "Python Driver",
      "cwe": "CWE-918",
      "title": "Forced local Unix socket connection via dot-sock KMS endpoint in client-side field encryption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-96747"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-97061",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "blackcandy-org",
      "product": "Black Candy",
      "cwe": "CWE-862",
      "title": "Black Candy through 3.2.1 Information Disclosure via Playlist Search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97061"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-97225",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "DbGate",
      "cwe": "CWE-74",
      "title": "DbGate JSON Runner runners.js code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97225"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-97226",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "DbGate",
      "cwe": "CWE-22",
      "title": "DbGate files-style Endpoint files.js fs.readFile path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97226"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-52853",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "docmost",
      "product": "docmost",
      "cwe": "CWE-269",
      "title": "Docmost: Privilege Escalation - ADMIN Can Invite Users as OWNER",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52853"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-4637",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Paessler GmbH",
      "product": "PRTG Network Monitor",
      "cwe": "CWE-79",
      "title": "Reflected Cross-Site Scripting via URL Path in Paessler PRTG Network Monitor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4637"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-17413",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "PowerVM Hypervisor",
      "cwe": "CWE-129",
      "title": "This Power System update is being released to address",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17413"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-17503",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "PowerVM Hypervisor",
      "cwe": "CWE-20",
      "title": "This Power System update is being released to address",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17503"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-17504",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "PowerVM Hypervisor",
      "cwe": "CWE-191",
      "title": "This Power System update is being released to address",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17504"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-48540",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "krayin",
      "product": "laravel-crm",
      "cwe": "CWE-79",
      "title": "Krayin CRM 2.2.6 Stored Template Injection XSS via Lead Title",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48540"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-48541",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "krayin",
      "product": "laravel-crm",
      "cwe": "CWE-79",
      "title": "Krayin CRM 2.2.6 Stored Template Injection XSS via Contact Name Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48541"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-48542",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "krayin",
      "product": "laravel-crm",
      "cwe": "CWE-79",
      "title": "Krayin CRM 2.2.6 Stored Template Injection XSS via Product Name Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48542"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-48543",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "krayin",
      "product": "laravel-crm",
      "cwe": "CWE-79",
      "title": "Krayin CRM 2.2.6 Stored Template Injection XSS via Web Form Description",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48543"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-82716",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Botslab",
      "product": "G980H",
      "cwe": "CWE-532",
      "title": "Botslab G980H Dashcams Insertion of Sensitive Information into Log File",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-82716"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-97062",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webkul",
      "product": "Aureus ERP",
      "cwe": "CWE-79",
      "title": "Aureus ERP through 1.6.0 Stored XSS via SVG File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97062"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-91121",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-79",
      "title": "Discourse: Chat upload filenames rendered as raw HTML in excerpts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91121"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-77825",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "ContextForge MCP Gateway",
      "cwe": "CWE-22",
      "title": "IBM ContextForge MCP Gateway is affected by path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77825"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-79680",
      "cvss_base": 4.5,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qt",
      "product": "qt",
      "cwe": "CWE-288",
      "title": "Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79680"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-56792",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Rugged Control Center (RCC)",
      "cwe": "CWE-287",
      "title": "Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56792"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2025-32000",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL Sametime",
      "cwe": "CWE-20",
      "title": "Insufficient Input Sanitization is addressed in HCL Sametime 12.0.4. It is recommended to upgrade to the latest version.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-32000"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-3253",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mailerlite",
      "product": "MailerLite – Signup forms (official)",
      "cwe": "CWE-862",
      "title": "MailerLite – Signup forms (official) <= 1.7.21 - Missing Authorization to Authenticated (Contributor+) Form Creation and Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3253"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-16302",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "brainstormforce",
      "product": "Spectra Legacy – Gutenberg Blocks",
      "cwe": "CWE-200",
      "title": "Spectra Legacy – Gutenberg Blocks <= 2.20.0 - Authenticated (Contributor+) Sensitive Information Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16302"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-18870",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "PowerVM Hypervisor",
      "cwe": "CWE-125",
      "title": "This Power System update is being released to address",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18870"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-48073",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "docmost",
      "product": "docmost",
      "cwe": "CWE-639",
      "title": "Docmost: Page export can include restricted same-space attachments through forged attachmentId",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48073"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-52850",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "docmost",
      "product": "docmost",
      "cwe": "CWE-639",
      "title": "Docmost: Broken access control in transclusion lookup API leaks sync-block content across private spaces",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52850"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-57177",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "python-social-auth",
      "product": "social-core",
      "cwe": "CWE-352",
      "title": "social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Backend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57177"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-62286",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "amir20",
      "product": "dozzle",
      "cwe": "CWE-200",
      "title": "Dozzle label filters do not restrict container event and statistics streams",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62286"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-77321",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mauriceboe",
      "product": "TREK",
      "cwe": "CWE-200",
      "title": "TREK MCP trip summary bypasses delegated OAuth read scopes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77321"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-79759",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Termix-SSH",
      "product": "Termix",
      "cwe": "CWE-639",
      "title": "Termix: Cross-User Information Disclosure via Missing Ownership Check in deploy-to-host Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-79759"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-81508",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "espressif",
      "product": "esp-idf",
      "cwe": "CWE-125",
      "title": "ESF-IDF: Heap Out-of-Bounds Read in Bluedroid A2DP Sink Media Packet Processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-81508"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-91132",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-346",
      "title": "Discourse: Wildcard iframe origin allowlist bypass via authority separators",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-91132"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-97311",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-862",
      "title": "Keycloak-services: keycloak-services: admin rest api role-groups endpoint discloses groups without authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97311"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-57179",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "python-social-auth",
      "product": "social-core",
      "cwe": "CWE-384",
      "title": "social-auth-core has a Session Fixation issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57179"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-84302",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-862",
      "title": "Discourse: Non-participant moderators can read, edit, and delete PM content through Discourse AI reviewables",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-84302"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-77797",
      "cvss_base": 3.6,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "Velociraptor",
      "cwe": "CWE-20",
      "title": "Velociraptor Prefetch parser out of bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-77797"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-17511",
      "cvss_base": 3.4,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "PowerVM Hypervisor",
      "cwe": "CWE-212",
      "title": "This Power System update is being released to address",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17511"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-18857",
      "cvss_base": 3.4,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "OPENBMC",
      "cwe": "CWE-125",
      "title": "This Power System update is being released to address",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18857"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-63630",
      "cvss_base": 3.4,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "alam00000",
      "product": "bentopdf",
      "cwe": "CWE-201",
      "title": "BentoPDF: Workflow Import Allows Unvalidated TSA URL Leading to PDF Hash Exfiltration via RFC 3161 Requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63630"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-18104",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2 Mirror for i",
      "cwe": "CWE-327",
      "title": "IBM Db2 Mirror for i is vulnerable to obtain sensitive information []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18104"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-19492",
      "cvss_base": 3.2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "PowerVM Hypervisor",
      "cwe": "CWE-457",
      "title": "This Power System update is being released to address",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-19492"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-73064",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "trustedfirmware",
      "product": "Mbed TLS",
      "cwe": "CWE-394",
      "title": "In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inject bytes into the start of the TLS stream. This only affects TLS 1.3 servers.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-73064"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-97179",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "O2OA",
      "cwe": "CWE-200",
      "title": "O2OA Cipher Connection CipherConnectionAction.java list information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97179"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-97224",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Excalidraw",
      "cwe": "CWE-79",
      "title": "Excalidraw Imported File restore.ts cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97224"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-97232",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "volotat",
      "product": "Anagnorisis",
      "cwe": "CWE-22",
      "title": "volotat Anagnorisis page.html start_streaming path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97232"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-97320",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YunaiV",
      "product": "ruoyi-vue-pro",
      "cwe": "CWE-918",
      "title": "YunaiV/zhijiantianya ruoyi-vue-pro AI Knowledge AiKnowledgeDocumentServiceImpl.java AiKnowledgeDocumentServiceImpl.readUrl server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97320"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-97321",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YunaiV",
      "product": "ruoyi-vue-pro",
      "cwe": "CWE-74",
      "title": "YunaiV/zhijiantianya ruoyi-vue-pro GoView Data Endpoint GoViewDataServiceImpl.java GoViewDataServiceImpl.getDataBySQL sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97321"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-97322",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YunaiV",
      "product": "ruoyi-vue-pro",
      "cwe": "CWE-79",
      "title": "YunaiV/zhijiantianya ruoyi-vue-pro File Upload FileController.java cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97322"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-97323",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YunaiV",
      "product": "ruoyi-vue-pro",
      "cwe": "CWE-22",
      "title": "YunaiV/zhijiantianya ruoyi-vue-pro File Upload MpMaterialServiceImpl.java getOriginalFilename path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97323"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-97325",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YunaiV",
      "product": "ruoyi-vue-pro",
      "cwe": "CWE-601",
      "title": "YunaiV/zhijiantianya ruoyi-vue-pro OAuth2 Client OAuth2ClientServiceImpl.java validOAuthClientFromCache redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97325"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-97365",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chonkie-inc",
      "product": "littrs",
      "cwe": "CWE-22",
      "title": "chonkie-inc littrs lib.rs mount path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97365"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-97366",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jhen0409",
      "product": "react-native-debugger",
      "cwe": "CWE-77",
      "title": "jhen0409 react-native-debugger Open in Editor window.js openDevTools os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97366"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-97368",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chillzhuang",
      "product": "SpringBlade",
      "cwe": "CWE-285",
      "title": "chillzhuang SpringBlade user-auth-info Endpoint UserServiceImpl.java UserServiceImpl.userInfo authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97368"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-97233",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "volotat",
      "product": "Anagnorisis",
      "cwe": "CWE-79",
      "title": "volotat Anagnorisis Media Filename PlaylistManager.js html cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97233"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-51994",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "mcp-remote versions 0.1.32 through 0.1.38 are vulnerable to Server-Side Request Forgery (SSRF) via the resource_metadata URL extracted from a remote MCP server's WWW-Authenticate header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51994"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-51996",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/utils.ts and the getServerUrlHash function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51996"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-51997",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the open() functions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51997"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-52001",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An issue in geelen mcp-remote 0.1.18 through 0.1.38 allows a remote attacker to obtain sensitive information via the SSE transport eventSourceInit fetch wrapper \" src/lib/utils.ts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52001"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-85491",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Catalyst-Seal",
      "cwe": "CWE-706",
      "title": "Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route a later one past an authorization check via a dispatch memo keyed on the request path alone",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-85491"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-88351",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An integer overflow vulnerability exists in the MPack Node API in MPack 1.1.1 on 32-bit platforms. When parsing a specially crafted MessagePack array32 or map32 object with an excessively large element count, the page allocation size calculation in mpack_tree_parse_children() can overflow size_t and produce an undersized allocation. Subsequent parsing writes mpack_node_data_t records beyond the allocated heap buffer, resulting in heap-buffer-overflow, memory corruption, and denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88351"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-88355",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "An incorrect buffer size calculation vulnerability exists in tinyexpr commit 4a7456e in new_expr(). For arity-0 expression nodes, including constants, variables, and zero-argument functions, the function allocates less memory than sizeof(te_expr) but treats the returned allocation as a complete te_expr object. This results in undefined behavior and can cause deterministic process termination in UBSan-instrumented builds.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88355"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-88358",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "simdjson 4.6.1 contains a one-byte out-of-bounds read vulnerability in dom::parser::parse_unpadded(). A specially crafted truncated JSON document whose final structural token closes a nested array or object can cause json_iterator::walk_document() to access buf[len] after the input buffer has been exhausted. This results in a heap out-of-bounds read and may cause application termination, leading to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88358"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-88359",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format(). When processing a specially crafted YAML document containing a very large literal or folded block scalar, the function repeatedly grows an internal buffer using alloca() inside a loop. The allocated stack memory is not released until the function returns, causing cumulative stack growth that can exceed the process stack limit and result in SIGSEGV and denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88359"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-88360",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "libvips 8.19.0 contains a memory access vulnerability when processing little-endian PFM images. If the PFM text header length is not a multiple of four bytes, the mmap-based loader can expose pixel data at an address that is not properly aligned for float access. vips_avg_scan() subsequently dereferences the buffer through a float pointer, resulting in undefined behavior and process termination on strict-alignment architectures or UBSan-instrumented builds, leading to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88360"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-88361",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "SumatraPDF 3.6.1 contains an integer overflow vulnerability in EngineMupdf::BuildPageLabelRec() when parsing PDF PageLabels /Nums entries.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88361"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-88362",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "MuJS e892c9fdb contains an incorrect numeric conversion vulnerability in jsR_isindex() in jsrun.c. A specially crafted JavaScript input containing an excessively large numeric array index can cause an out-of-range floating-point value to be converted to an integer without proper range validation. This results in undefined behavior and can cause process termination, leading to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88362"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-88365",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "minimp3 commit ea99364f contains an integer overflow vulnerability in mp3dec_skip_id3v1() when parsing the APEv2 tag-size field.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88365"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-88366",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__pathArcTo() when parsing SVG arc commands. A specially crafted SVG document containing extreme arc radius values can cause intermediate arc calculations to produce a NaN delta angle. The function subsequently converts this NaN value to int without validating that it is finite and representable, resulting in undefined behavior and process termination, leading to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88366"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-88367",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "NanoSVG 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__curveDivs() during SVG stroke rasterization. A specially crafted SVG document containing an extremely large stroke-width can cause floating-point rounding to produce a zero subdivision angle. The subsequent arc division yields infinity, which is converted to int without range validation, resulting in undefined behavior and process termination, leading to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88367"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-88369",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "zserge jsmn commit 25647e6 is vulnerable to Buffer Overflow in example/jsondump.c dump().",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88369"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-88370",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "libconfini 1.16.4 contains a heap out-of-bounds write condition involving the bundled load_ini_buffer.h utility and strip_ini_cache(). The bundled utility allocates exactly ini_length bytes, while strip_ini_cache() unconditionally writes a NUL terminator at ini_source[ini_length], requiring an additional writable byte. Applications using the bundled allocation pattern can trigger deterministic heap memory corruption when processing any non-empty INI input, resulting in denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88370"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-88371",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "ZBar commit 2ea2ca58 contains an undefined-behavior vulnerability in the Code 128 decode6() function. When processing specially crafted Code 128 input, decode_e() can return -1 for an invalid edge pattern, and decode6() subsequently left-shifts this negative signed value while constructing the edge signature. The operation invokes undefined behavior and can terminate trap-mode UBSan builds with SIGILL, resulting in denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88371"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-88373",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "libde265 commit 4d45a6b contains a NULL pointer dereference vulnerability in the NAL parsing path. When de265_push_NAL() is called with a zero-length NAL unit, the resulting NAL_unit may retain a NULL backing buffer, which is subsequently passed as the destination argument to memcpy() in NAL_unit::set_data(). Although the copy length is zero, this violates the nonnull requirement of memcpy() and results in undefined behavior, causing process termination in UBSan-instrumented builds and denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88373"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-88377",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Bento4 1.6.0.0 contains an integer underflow vulnerability in the avcC and hvcC configuration atom parsers. A specially crafted MP4 file containing an atom with a declared size smaller than AP4_ATOM_HEADER_SIZE can cause AP4_AvccAtom::Create() or AP4_HvccAtom::Create() to underflow the payload-size calculation. The resulting oversized buffer operation can cause invalid or NULL pointers to be passed to the AP4_DataBuffer copy path, resulting in application termination and denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88377"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-88378",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "QuickJS commit 04be24600 contains a heap out-of-bounds write condition in JS_ReadFunctionTag().",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88378"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-88383",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "libical 4.0.6 contains an incompatible function pointer in icalparameter_string_to_kind(). When parsing iCalendar data containing a parameterized property, the function passes icalparameter_compare_kind_map() to bsearch() through an incompatible comparator function pointer type. bsearch() invokes the callback through the mismatched type, resulting in undefined behavior and process termination, leading to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88383"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-88385",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Mini-XML 4.0.5 contains a memory leak vulnerability in mxml_load_data() during malformed XML parsing. Specially crafted XML input can cause text nodes allocated by mxmlNewText() to become unlinked before a parse error transfers control to the cleanup path. These orphaned nodes are not released, resulting in a persistent memory leak on each parsing attempt. Repeated attacker-controlled requests can cause cumulative memory exhaustion and denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88385"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-88386",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "libsndfile 1.2.2 contains a misaligned memory access issue in psf_binheader_readf() while parsing WAV fmt chunks. A specially crafted WAV file can cause the function to cast an unaligned destination address to unsigned int * and perform a 4-byte store. This results in undefined behavior leading to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88386"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-88387",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "LibRaw 0.22.0 contains an incorrect numeric conversion vulnerability in LibRaw::parse_tiff_ifd() when processing TIFF tag 0x00fe (NewSubfileType). A specially crafted RAW, TIFF, or DNG file can supply an attacker-controlled NewSubfileType value outside the range of a signed int. The parser converts this value and narrows it to int without performing range validation. This out-of-range conversion triggers undefined behavior, resulting in process termination and denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88387"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-88388",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": null,
      "title": "Espruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow vulnerability in the JavaScript error stack-trace handling path on 64-bit builds. A remote attacker can supply JavaScript input that triggers an exception and reaches jslPrintTokenLineMarker(), which passes the address of a 4-byte int column variable to jsvGetLineAndCol() as a size_t pointer. jsvGetLineAndCol() performs an 8-byte write through the mismatched pointer, overwriting adjacent stack memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-88388"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-93205",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/arm-smmu-v3: Manage teardown with devm",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93205"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-93206",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "PCI/proc: Use file_ns_capable() when checking config space read access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93206"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-93208",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "kasan: fix cache shrink race with CPU hotplug",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93208"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-93209",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93209"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-93210",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: harden DFS cache against invalid target hints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93210"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-93211",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: initialize DRC hash table before registering shrinker",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93211"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-93212",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nfsd: guard nfsd_serv deref in nfsd_file_net_dispose",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93212"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-93213",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "of: fix out-of-bounds read in of_alias_scan() stem parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93213"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-93214",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: f_tcm: fix deadlock in usbg_make_tpg()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93214"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-93215",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cdx: Fix double free when sysfs file creation fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93215"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-93216",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/page_owner: use memcg_data snapshot to avoid TOCTOU in print_page_owner_memcg()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93216"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-93217",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/madvise: skip device-private PMDs in cold and pageout walks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93217"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-93218",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/huge_memory: skip device-private PMDs in madvise_free_huge_pmd",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93218"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-93219",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "clocksource/drivers/timer-sun4i: Advertise a real minimum delta",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93219"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-93220",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sched_ext: Keep kick_sync waiting on the rq's own CPU",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93220"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-93222",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "signal: avoid shared siginfo namespace rewrites",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93222"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-93223",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "staging: media: tegra-video: fix of_node_put() on VIP parse errors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93223"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-93226",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipv6: use RCU iterator to dump route exceptions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93226"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-93227",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/mm_init: deferred_grow_zone(): fix out-of-range first_deferred_pfn",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93227"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-93230",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/hugetlb: initialize gigantic bootmem hugepage struct pages earlier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93230"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-93231",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "lockd: fix swapped arguments in nlmsvc_match_ip()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93231"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-93232",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/hugetlb: fix boot panic with CONFIG_DEBUG_VM and HVO bootmem pages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93232"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-93233",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/nouveau/dmem: fix callocated underflow on large folio split",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93233"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-93234",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/gud: validate TV mode names before creating enum property",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93234"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-93235",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "f2fs: fix to zero post-EOF data when extending file size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93235"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-93236",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93236"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-93238",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/vfio-ap: fix potential use of uninitialized apm_filtered bitmap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93238"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-93239",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "arm64: mm: Fix the lockless page-table walk in show_pte()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93239"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-93240",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "memcg: make the v1 soft limit knob inert",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93240"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-93241",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "memcg: bypass the reclaim and oom killer for dying tasks once oom_reaper is done",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93241"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-93242",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: qla2xxx: Fix response queue over-consumption in __qla_consume_iocb()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93242"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-93243",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/secretmem: properly account locked pages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93243"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-93244",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/sysfb: simpledrm: Improve stride validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93244"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-93245",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "apparmor: policy_int make sure list heads are initialized before fail path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93245"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-93246",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "octeontx2-af: fix out-of-bounds read setting MSI-X irq affinity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93246"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-93247",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: mgmt: fix 'hdev->discovery.uuids' NULL dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93247"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-93248",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/xe: don't WARN on kernel job timeout when device already wedged",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93248"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-93249",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "spi: amlogic-spisg: Make sure clk_init_data is fully initialized",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93249"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-93251",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ACPI: bus: Introduce acpi_bus_get_primary_device()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93251"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-93252",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ocfs2: fix circular locking dependency in ocfs2_init_acl()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93252"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-93253",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sched/isolation: Defer freeing of cpumask memblock memory to initcall",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93253"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-93254",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "arm64: entry: Avoid unnecessary local_irq_disable() on kernel exit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93254"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-93255",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: make sure EXTENT_BUFFER_READING is cleared under refs_lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93255"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-93256",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "arm64: hibernate: mask DAIF before restoring hibernated kernel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93256"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-93257",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "block: handle nogenerate/noverify properly in fs-integrity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93257"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-93258",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ocfs2: do not use make_bad_inode() in ocfs2_read_inode_block_full()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93258"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-93259",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "powerpc/irq: Fix missing r2 clobber in PCREL inline assembly",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93259"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-93261",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "locking/lockdep: Fix NULL pointer dereference in __lock_set_class()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93261"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-93263",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "clk: eswin: Zero-initialize stack-allocated clk_init_data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93263"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-93264",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/efa: Fix PBL chunk length computation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93264"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-93266",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "arm64: RSI: fix field-spanning write warning in attestation token init",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93266"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-93267",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/core: Fix potential use after free in uverbs_free_dmah()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93267"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-93268",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ext4: skip extra isize expansion during mount to prevent deadlock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93268"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-93269",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ext4: fix circular lock dependency in ext4_ext_migrate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93269"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-93270",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Disallow interpreter fallback for BPF_ADDR_PERCPU insn",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93270"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-93271",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93271"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-93272",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "remoteproc: qcom_wcnss: Fix handling the lack of PD regulators in v3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93272"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-93273",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "regulator: tps6594: Fix device node reference leaks in multiphase loop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93273"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-93274",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "pinctrl: bcm2835: Don't remove an unregistered GPIO chip",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93274"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-93275",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "perf/x86/intel/pt: Fix stop/start with no update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93275"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-93276",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "phy: renesas: phy-rcar-gen3-usb2: Fix devm action registration for disabled VBUS regulator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93276"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-93278",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93278"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-93279",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93279"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-93281",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: rtw89: fix HE extended capability length check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93281"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-93283",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "i3c: master: Fix device_register() error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93283"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-93285",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "f2fs: embed f2fs_gc_kthread in f2fs_sb_info",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93285"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-93286",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: appletalk: fix NULL pointer dereference in aarp_send_ddp()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93286"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-93781",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "scsi: core: Do not block on tag allocation in scsi_eh_lock_door()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93781"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-93783",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: RFCOMM: validate skb length in rfcomm_recv_frame",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93783"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-93784",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: cfg80211: validate IEs in cfg80211_wext_siwgenie()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93784"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-93785",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cifs: validate idmap key payload length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93785"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-93788",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: iwlwifi: acpi: validate WGDS table revision index",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93788"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-93789",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: iwlwifi: bound aligned TLV advance in FW parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93789"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-93791",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: iwlwifi: mvm: add a check on the tid coming from the firmware",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93791"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-93792",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: iwlwifi: mvm: fix a possible underflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93792"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-93794",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb/client: flush dirty data before punching a hole",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93794"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-93795",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "blk-cgroup: fix leaks and online flag on radix_tree_insert failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93795"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-93797",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: iwlwifi: mvm: fix an off-by-1 boundary check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93797"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-93800",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: fix use-after-free on reloc root after error in insert_dirty_subvol()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93800"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-93802",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: rsi: validate beacon length before fixed buffer copy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93802"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-93803",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: libipw: fix key index receive bound checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93803"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-93804",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mac80211: ibss: wait for in-flight TX on disconnect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93804"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-93805",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: cfg80211: validate rx/tx MLME callback frame lengths before access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93805"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-93807",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: rsi: avoid reading TKIP MIC keys for non-TKIP ciphers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93807"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-93808",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: usb-audio: caiaq: validate EP1 reply lengths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93808"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-93809",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: flush pending RCU callbacks on module unload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93809"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-93811",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: Fix acl.sd_buf memory leak and invalid sd_size error handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93811"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-93812",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93812"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-93814",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "spi: core: Abort active target transfer on controller suspend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93814"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-93815",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: au1000: move free_irq out of the close-time spinlocked section",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93815"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-93818",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "PCI: plda: Protect root bus removal with rescan lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93818"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2026-93819",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "PCI: mediatek: Protect root bus removal with rescan lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93819"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-93820",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "PCI: rockchip: Protect root bus removal with rescan lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93820"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-93821",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "PCI: altera: Protect root bus removal with rescan lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93821"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2026-93822",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "PCI: iproc: Protect root bus removal with rescan lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93822"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-93823",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdkfd: Let driver decide buffer size at AMDKFD_IOC_GET_DMABUF_INFO ioctl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93823"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-93824",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tls: reject the combination of TLS and sockmap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93824"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-93825",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "spi: Add NULL check for spi_get_device_id() in spi_get_device_match_data()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93825"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2026-93828",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "exfat: fix handling of damaged volume in exfat_create_upcase_table()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93828"
    },
    {
      "rank": 478,
      "cve_id": "CVE-2026-93829",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "smb: client: fix races in cifsd thread creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-93829"
    },
    {
      "rank": 479,
      "cve_id": "CVE-2026-97230",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "IO-Socket-SSL-SelfCertificate",
      "cwe": "CWE-506",
      "title": "IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97230"
    },
    {
      "rank": 480,
      "cve_id": "CVE-2026-97407",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: rockchip: rockchip_pdm: Handle runtime PM resume failures in set_fmt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97407"
    },
    {
      "rank": 481,
      "cve_id": "CVE-2026-97408",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: L2CAP: validate connectionless PSM length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97408"
    },
    {
      "rank": 482,
      "cve_id": "CVE-2026-97410",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netconsole: take target_cleanup_list_lock in drop_netconsole_target()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97410"
    },
    {
      "rank": 483,
      "cve_id": "CVE-2026-97411",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: ibm: emac: mal: fix potential system hang in mal_remove()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97411"
    },
    {
      "rank": 484,
      "cve_id": "CVE-2026-97412",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "pds_core: quiesce DMA before freeing resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97412"
    },
    {
      "rank": 485,
      "cve_id": "CVE-2026-97414",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: mediatek: mt8365-afe-pcm: fix possible NULL-pointer dereferences in mt8365_afe_suspend()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97414"
    },
    {
      "rank": 486,
      "cve_id": "CVE-2026-97416",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "btrfs: balance: fix potential bg lookup failure in btrfs_may_alloc_data_chunk()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97416"
    },
    {
      "rank": 487,
      "cve_id": "CVE-2026-97418",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: es18xx: check control allocation before private data setup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97418"
    },
    {
      "rank": 488,
      "cve_id": "CVE-2026-97419",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hsr: broadcast netlink notifications in the device's net namespace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97419"
    },
    {
      "rank": 489,
      "cve_id": "CVE-2026-97420",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: NUL-terminate replaced sysctl value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97420"
    },
    {
      "rank": 490,
      "cve_id": "CVE-2026-97422",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdkfd: fix SMI event cross-process information leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97422"
    },
    {
      "rank": 491,
      "cve_id": "CVE-2026-97423",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "cxl/region: Validate partition index before array access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97423"
    },
    {
      "rank": 492,
      "cve_id": "CVE-2026-97424",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu/ras: add ras_suspend callback and use it for cp_ecc_error_irq",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97424"
    },
    {
      "rank": 493,
      "cve_id": "CVE-2026-97425",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: fix buffer overflow during vBIOS update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97425"
    },
    {
      "rank": 494,
      "cve_id": "CVE-2026-97426",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu/pm: fix SmartShift bias sysfs store PM refcount on parse error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97426"
    },
    {
      "rank": 495,
      "cve_id": "CVE-2026-97427",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amd/pm: bound pp_dpm_set_pp_table() memcpy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97427"
    },
    {
      "rank": 496,
      "cve_id": "CVE-2026-97430",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xhci: Prevent queuing new commands if xhci is inaccessible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97430"
    },
    {
      "rank": 497,
      "cve_id": "CVE-2026-97431",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amd/display: Avoid DPMS-on for phantom stream",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97431"
    },
    {
      "rank": 498,
      "cve_id": "CVE-2026-97432",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: iwlwifi: mvm: fix P2P-Device binding handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97432"
    },
    {
      "rank": 499,
      "cve_id": "CVE-2026-97434",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dpaa2-switch: fix handling of NAPI on the remove path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97434"
    },
    {
      "rank": 500,
      "cve_id": "CVE-2026-97435",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: dsa: sja1105: flower: reject cross-chip redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97435"
    },
    {
      "rank": 501,
      "cve_id": "CVE-2026-97436",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dpaa2-switch: rework FDB management on the bridge leave path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97436"
    },
    {
      "rank": 502,
      "cve_id": "CVE-2026-97439",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fs/ntfs3: preserve non-DOS attribute bits in system.dos_attrib",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97439"
    },
    {
      "rank": 503,
      "cve_id": "CVE-2026-97440",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: qrtr: fix node refcount leak on ctrl packet alloc failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97440"
    },
    {
      "rank": 504,
      "cve_id": "CVE-2026-97441",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ata: ahci: fail probe if BAR too small for claimed ports",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97441"
    },
    {
      "rank": 505,
      "cve_id": "CVE-2026-97443",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "perf/ftrace: Fix WARNING in __unregister_ftrace_function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97443"
    },
    {
      "rank": 506,
      "cve_id": "CVE-2026-97446",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ACPICA: Fix NULL pointer dereference in acpi_ns_custom_package()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97446"
    },
    {
      "rank": 507,
      "cve_id": "CVE-2026-97447",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ACPICA: Enhance OEM ID and Table ID validation in acpi_ex_load_table_op()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97447"
    },
    {
      "rank": 508,
      "cve_id": "CVE-2026-97449",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ACPICA: Add package limit checks in parser functions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97449"
    },
    {
      "rank": 509,
      "cve_id": "CVE-2026-97453",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ACPICA: validate byte_count in acpi_ps_get_next_package_length()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97453"
    },
    {
      "rank": 510,
      "cve_id": "CVE-2026-97456",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ACPICA: Fix condition check in acpi_ps_parse_loop()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97456"
    },
    {
      "rank": 511,
      "cve_id": "CVE-2026-97472",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipv6: addrconf: fix temp address generation after prefix deprecation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97472"
    },
    {
      "rank": 512,
      "cve_id": "CVE-2026-97473",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "powercap: intel_rapl: Fix memory leak in rapl_add_package_cpuslocked()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97473"
    },
    {
      "rank": 513,
      "cve_id": "CVE-2026-97475",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "thermal/drivers/tegra/soctherma: Switch to devm cooling device registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97475"
    },
    {
      "rank": 514,
      "cve_id": "CVE-2026-97476",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "rds: filter RDS_INFO_* getsockopt by caller's netns",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97476"
    },
    {
      "rank": 515,
      "cve_id": "CVE-2026-97477",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/counter: Fix num_counters leak on bind_qp failure in alloc_and_bind()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97477"
    },
    {
      "rank": 516,
      "cve_id": "CVE-2026-97479",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "driver core: Avoid warning when removing a device while its supplier is unbinding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97479"
    },
    {
      "rank": 517,
      "cve_id": "CVE-2026-97480",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tty: serial: 8250: protect against NULL uart->port.dev in register",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97480"
    },
    {
      "rank": 518,
      "cve_id": "CVE-2026-97481",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "serial: 8250: fix possible ISR soft lockup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97481"
    },
    {
      "rank": 519,
      "cve_id": "CVE-2026-97482",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: goku_udc: avoid NULL deref of dev->driver in INT_USBRESET log",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97482"
    },
    {
      "rank": 520,
      "cve_id": "CVE-2026-97483",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: core: hcd: fix possible deadlock in rh control transfers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97483"
    },
    {
      "rank": 521,
      "cve_id": "CVE-2026-97484",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usbip: vhci_hcd: fix NULL deref in status_show_vhci",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97484"
    },
    {
      "rank": 522,
      "cve_id": "CVE-2026-97485",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "omfs: handle set_blocksize failures",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97485"
    },
    {
      "rank": 523,
      "cve_id": "CVE-2026-97486",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hpfs: handle set_blocksize failures",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97486"
    },
    {
      "rank": 524,
      "cve_id": "CVE-2026-97487",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "jfs: handle set_blocksize failures",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97487"
    },
    {
      "rank": 525,
      "cve_id": "CVE-2026-97488",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "qnx4: handle set_blocksize failures",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97488"
    },
    {
      "rank": 526,
      "cve_id": "CVE-2026-97489",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bfs: handle set_blocksize failures",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97489"
    },
    {
      "rank": 527,
      "cve_id": "CVE-2026-97490",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "affs: handle set_blocksize failures",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97490"
    },
    {
      "rank": 528,
      "cve_id": "CVE-2026-97491",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/rds: Don't sleep inside rds_ib_conn_path_shutdown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97491"
    },
    {
      "rank": 529,
      "cve_id": "CVE-2026-97492",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mac80211: don't call ieee80211_handle_reconfig_failure when not needed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97492"
    },
    {
      "rank": 530,
      "cve_id": "CVE-2026-97493",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: Bound GPIO I2C table entry count from VBIOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97493"
    },
    {
      "rank": 531,
      "cve_id": "CVE-2026-97494",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: validate and share PSP fw_pri_buf copies via psp_copy_fw",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97494"
    },
    {
      "rank": 532,
      "cve_id": "CVE-2026-97495",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdkfd: Check bounds on allocate_doorbell",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97495"
    },
    {
      "rank": 533,
      "cve_id": "CVE-2026-97498",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu/userq: pin mqd and fw object bo to avoid eviction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97498"
    },
    {
      "rank": 534,
      "cve_id": "CVE-2026-97499",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "coresight: perf: Retrieve path and source from event data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97499"
    },
    {
      "rank": 535,
      "cve_id": "CVE-2026-97500",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: rtw89: phy: check length before parsing PHY status IE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97500"
    },
    {
      "rank": 536,
      "cve_id": "CVE-2026-97501",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "pinctrl: mediatek: paris: bypass pinctrl GPIO layer in set GPIO direction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97501"
    },
    {
      "rank": 537,
      "cve_id": "CVE-2026-97502",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mmc: davinci: avoid NULL deref of host->data in IRQ handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97502"
    },
    {
      "rank": 538,
      "cve_id": "CVE-2026-97503",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "genirq/proc: Size interrupt directory names for 10-digit interrupt numbers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97503"
    },
    {
      "rank": 539,
      "cve_id": "CVE-2026-97504",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "watchdog: lenovo_se10_wdt: Fix use-after-free and resource leak risk",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97504"
    },
    {
      "rank": 540,
      "cve_id": "CVE-2026-97505",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "PCI/sysfs: Add CAP_SYS_ADMIN check to __resource_resize_store()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97505"
    },
    {
      "rank": 541,
      "cve_id": "CVE-2026-97506",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: ixp4xx - fix buffer chain unwind on allocation failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97506"
    },
    {
      "rank": 542,
      "cve_id": "CVE-2026-97507",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: dm1105: fix missing error check for dma_alloc_coherent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97507"
    },
    {
      "rank": 543,
      "cve_id": "CVE-2026-97510",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "thunderbolt: Release request if tb_cfg_request() fails in __tb_xdomain_response()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97510"
    },
    {
      "rank": 544,
      "cve_id": "CVE-2026-97511",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mac80211: avoid out-of-bounds access in monitor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97511"
    },
    {
      "rank": 545,
      "cve_id": "CVE-2026-97512",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "spi: spi-qcom-qspi: Fix incomplete error handling in runtime PM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97512"
    },
    {
      "rank": 546,
      "cve_id": "CVE-2026-97514",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: chips-media: wave5: Fix Reports from Kernel Lock Validator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97514"
    },
    {
      "rank": 547,
      "cve_id": "CVE-2026-97515",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "i3c: master: svc: Prevent IRQ storm from false SLVSTART on NPCM845",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97515"
    },
    {
      "rank": 548,
      "cve_id": "CVE-2026-97516",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: rtw88: Add NULL check for chip->edcca_th in rtw_fw_adaptivity_result()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97516"
    },
    {
      "rank": 549,
      "cve_id": "CVE-2026-97517",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: nl80211: reject beacons with bad HE operation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97517"
    },
    {
      "rank": 550,
      "cve_id": "CVE-2026-97518",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: cfg80211: reject duplicate wiphy cipher suite entries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97518"
    },
    {
      "rank": 551,
      "cve_id": "CVE-2026-97519",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/xe: Fix null pointer dereference in devcoredump cleanup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97519"
    },
    {
      "rank": 552,
      "cve_id": "CVE-2026-97521",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "gfs2: fix quota init duplicate scan",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97521"
    },
    {
      "rank": 553,
      "cve_id": "CVE-2026-97636",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": null,
      "epss_percentile": null,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow HashiCorp provider",
      "cwe": "CWE-639",
      "title": "Apache Airflow HashiCorp provider: HashiCorp Vault secrets backend: team-scope guard bypass via user-controlled key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-97636"
    }
  ],
  "transactions": [
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-5430",
      "detail": "ADDED TO KEV — CVE-2026-5430 (WSO2 Universal Gateway). Remediation due September 27, 2026."
    },
    {
      "type": "KEV_ADDED",
      "cve_id": "CVE-2026-71362",
      "detail": "ADDED TO KEV — CVE-2026-71362 (Adobe Commerce). Remediation due September 27, 2026."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2016-20096",
      "detail": "EXPLOIT PUBLISHED — CVE-2016-20096 (Kunshi Network Technology Co., Ltd. Linknat VOS3000). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2020-37268",
      "detail": "EXPLOIT PUBLISHED — CVE-2020-37268 (rocq-prover rocq). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-0108",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-0108 (Palo Alto Networks Cloud NGFW). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-30066",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-30066 (tj-actions changed-files). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4637",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4637 (Paessler GmbH PRTG Network Monitor). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48594",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48594 (elixir-tesla tesla). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48595",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48595 (elixir-tesla tesla). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48596",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48596 (elixir-tesla tesla). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54460",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54460 (open-reception appointment-booking-software). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55194",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55194 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55654",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55654 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56100",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56100 (SpringBlade). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56812",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56812 (phoenixframework phoenix). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-57851",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-57851 (Micro-Star International (MSI) KernCoreLib64.sys). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63633",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63633 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63635",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63635 (AcademySoftwareFoundation OpenImageIO). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63769",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63769 (huginn). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67549",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67549 (AcademySoftwareFoundation OpenImageIO). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-70619",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-70619 (odysseus-dev odysseus). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-72703",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-72703 (rocq-prover rocq). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-72704",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-72704 (rocq-prover rocq). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-72705",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-72705 (rocq-prover rocq). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-72714",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-72714 (rocq-prover rocq). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-72777",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-72777 (DayuanJiang next-ai-draw-io). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-77525",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-77525 (1Panel-dev MaxKB). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82017",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82017 (IGEL OS 12). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-82280",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-82280 (QuivrHQ quivr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-84810",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-84810 (claude-world claude-skill-antivirus). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86175",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86175 (netbox-community netbox). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86176",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86176 (netbox-community netbox). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86177",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86177 (pterodactyl panel). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-86178",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-86178 (pixelfed). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87927",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87927 (MaxSite CMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87928",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87928 (MaxSite CMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87929",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87929 (MaxSite CMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-87930",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-87930 (MaxSite CMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-89260",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-89260 (moxi624 MoguBlog). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-89261",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-89261 (moxi624 MoguBlog). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-89262",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-89262 (moxi624 MoguBlog). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-89263",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-89263 (moxi624 MoguBlog). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-89264",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-89264 (moxi624 MoguBlog). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-89265",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-89265 (moxi624 MoguBlog). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90939",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90939 (201206030 novel-plus). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90940",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90940 (201206030 novel-plus). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90941",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90941 (201206030 novel-plus). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-90942",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-90942 (casdoor). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91143",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91143 (snail007 goproxy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91752",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91752 (GNU libextractor). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91945",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91945 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91949",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91949 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91950",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91950 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91951",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91951 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91952",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91952 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91953",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91953 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91954",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91954 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91955",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91955 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91956",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91956 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91957",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91957 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91958",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91958 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91959",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91959 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91960",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91960 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91993",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91993 (dromara Jpom). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91994",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91994 (semaphoreui semaphore). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91995",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91995 (pig-mesh pig). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91996",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91996 (dromara lamp-cloud). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91997",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91997 (evolution-foundation evolution-api). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-91998",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-91998 (casdoor). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92918",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92918 (cjbi admin3). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92919",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92919 (cjbi admin3). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92920",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92920 (cjbi admin3). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-92921",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-92921 (cjbi admin3). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93972",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93972 (SourceCodester Online Reviewer Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-93977",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-93977 (code-projects Assessment Management). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94003",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94003 (Comfast CF-N1-S). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94030",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94030 (SerenityOS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94035",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94035 (SourceCodester Drug Recommendation System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94040",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94040 (vas3k TaxHacker). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94045",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94045 (newbee-ltd newbee-mall). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94092",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94092 (dmlc dgl). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94097",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94097 (Netcore NBR200V2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94102",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94102 (WuzhiCMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94109",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94109 (openEQUELLA). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94144",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94144 (drogonframework drogon). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94150",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94150 (Omega Solution HRM OS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94214",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94214 (ST Engineering iDirect Evolution). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94411",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94411 (jishenghua jshERP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94426",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94426 (xuxueli xxl-job). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94493",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94493 (Gigatech PDV5701). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94495",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94495 (jishenghua jshERP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94532",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94532 (dromara lamp-cloud). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-94540",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-94540 (MrPear DesktopSMS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-96551",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-96551 (sfturing hosp_order). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-96552",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-96552 (sfturing hosp_order). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-96556",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-96556 (Neethuharii CafeManagement). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-96601",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-96601 (Abdurrab5 online-makeup-store). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-96603",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-96603 (Abdurrab5 online-makeup-store). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-96604",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-96604 (SoftNews Media Group DataLife Engine). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-96676",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-96676 (Fast FAC1900R). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-96680",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-96680 (ByteDance Coze Scraper Extension). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-87491",
      "detail": "DUE DATE PASSED — CVE-2026-87491 (Google Chrome). CISA remediation deadline was September 23, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2008-4128",
      "detail": "RESCORED — CVE-2008-4128. CVSS 4.3 → 8.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-48384",
      "detail": "RESCORED — CVE-2025-48384 (git). CVSS 8.1 → 8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-11538",
      "detail": "RESCORED — CVE-2026-11538 (IBM WebSphere Application Server). CVSS 3.7 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-69553",
      "detail": "RESCORED — CVE-2026-69553 (Microsoft Windows 10 Version 1809). CVSS 7.1 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-70570",
      "detail": "RESCORED — CVE-2026-70570 (Microsoft Windows 10 Version 1607). CVSS 7.5 → 8.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-70575",
      "detail": "RESCORED — CVE-2026-70575 (Microsoft Windows 11 version 23H2). CVSS 5.3 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-88097",
      "detail": "RESCORED — CVE-2026-88097 (Microsoft Edge (Chromium-based)). CVSS 8.1 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-94054",
      "detail": "RESCORED — CVE-2026-94054 (Exim). CVSS 7 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-94055",
      "detail": "RESCORED — CVE-2026-94055 (Exim). CVSS 3.7 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-94057",
      "detail": "RESCORED — CVE-2026-94057 (Exim). CVSS 4 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-96739",
      "detail": "RESCORED — CVE-2026-96739 (SEMCMS). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-96751",
      "detail": "RESCORED — CVE-2026-96751 (pmTicket Project-Management-Software). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-96762",
      "detail": "RESCORED — CVE-2026-96762 (kvcache-ai mooncake). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-78225",
      "detail": "PATCH SHIPPED — CVE-2026-78225 (Wärtsilä FOS-Onboard). Fixed in FOS-Onboard 5.08.4052.01."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-81855",
      "detail": "PATCH SHIPPED — CVE-2026-81855 (Wärtsilä FOS-Onboard). Fixed in FOS-Onboard 5.08.4052.01."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-93345",
      "detail": "PATCH SHIPPED — CVE-2026-93345 (MikroTik RouterOS). Fixed in RouterOS 7.25beta4."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-96512",
      "detail": "PATCH SHIPPED — CVE-2026-96512 (Red Hat Hardened Images). Fixed in Red Hat Hardened Images 1.9.17-16.p2.2.hum1."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
